OSINTTOOLS / POLICY

Privacy Policy

This policy describes the data flows implemented by the current OSINT Tools website and separates activity on this site from activity on independently operated resources.

Applies to
osinttools.me
Last updated
September 9, 2026

The OSINT Tools website

This policy covers visits to https://osinttools.me, directory browsing, favorites, tool submissions, Google sign-in and the site interfaces described below. It does not govern the OSINT tools, databases, repositories or other destinations reached through directory links.

The description is based on the current application code and configuration. Hosting platforms, network intermediaries, email providers and linked services can process data under their own terms and policies.

Activity and the data it can involve

Browse the directory
Standard web request data, an OSINT Tools visitor identifier cookie, analytics and third-party page assets.
Search for a tool
The keyword is sent to the site's backend for suggestions. The current code contains no search-history table or browser-storage routine.
Save a favorite
A user record tied to the visitor identifier, the selected tool ID, timestamps and a country code supplied in the request when available.
Submit a tool
The website name and URL, selected categories, description, CLI indicator, review status, timestamps and requesting IP address, linked to the submitting user record.
Sign in with Google
Google account ID, email address, display name and profile image returned by the requested profile scopes.
Contact the site
Your email address, message and attachments chosen by you; contact uses a mail link rather than an on-site form.
Open an external tool
The destination handles the subsequent visit under its own privacy practices.

Submissions, account details and correspondence

Browsing does not require you to type a name or email address into OSINT Tools. If you submit a tool, the site stores the website name and URL, primary and optional secondary category, description, CLI indicator, review status, submission timestamps and requesting IP address. The IP address is used to enforce a limit of three submissions per user or IP address during a 12-hour period. If you choose Google sign-in, the account fields described in section 05 are returned through Google's OAuth flow. If you send an email, the address, message body and any attachments you add are processed by the mail services involved.

Do not send passwords, authentication codes, private case files or sensitive personal data that is not needed to explain the request.

What reaches the application and its infrastructure

A web request ordinarily exposes the requesting IP address and technical headers to the server, hosting stack and network intermediaries needed to deliver the page. The application specifically reads the CF-IPCountry country header when it is supplied. If a visitor first creates a database-backed user record by saving a favorite or making a permitted unbound submission, that country code is stored with the record.

The application is configured to write file-based logs, including application and service errors. The repository does not define a retention schedule for those logs and does not establish what additional access or security logging may be configured by the hosting provider or reverse proxy.

IP address distinction

Tool-submission records store the requesting IP address for rate limiting. The current user and favorites records do not contain an IP-address field. An IP address can also be visible to the server, network provider, analytics service or their logs.

Visitor records and Google sign-in

The favorites feature can create a user record without Google sign-in. That record uses the OSINT Tools visitor cookie as its identifier and can contain a country code, creation time and update time. Favorite records connect that user record to a tool ID and record when the favorite was added.

The site can be configured either to require Google sign-in for tool submissions or to allow submissions linked only to the visitor record. Google sign-in requests the openid, email and profile scopes. It stores the Google account identifier, email address, display name and profile image URL returned through that flow, then associates them with the site's user record. Authentication requests and account data returned by Google are also processed by Google.

Cookies used by current site features

osinttools_user_id
A random visitor identifier set when the site is loaded. The configured lifetime is ten years. It connects favorites, submissions and an optional Google account to the same site user record.
google_callback_refer
Stores the referring page for up to one hour during the Google sign-in redirect flow.
osint_no_google_prompt
Stores a 24-hour preference after a visitor dismisses the Google sign-in reminder shown when adding a favorite.
Framework session
ThinkPHP session support is enabled in configuration, although these directory pages do not implement a separate custom session-based profile feature.

The current project JavaScript does not use localStorage or sessionStorage. Analytics, advertising and other third-party scripts can use their own browser storage according to their configurations and policies.

Google Analytics and advertising code

Pages load Google Analytics through a site measurement ID and initialize the Google dataLayer. They also load the Google AdSense script. These requests can provide Google with network and browser information and can involve cookies or similar identifiers controlled by Google.

The OSINT Tools repository does not define Google's internal retention or advertising-profile rules. Those details are governed by Google's configuration and published policies rather than this codebase.

External services loaded by the site

Google
Optional OAuth sign-in, Analytics, AdSense and Google Fonts.
Code CDNs
Tailwind CSS, Font Awesome through cdnjs, and jQuery are requested from third-party content-delivery hosts.
Footer badges
Badge images are requested from the directory and launch sites named in the footer, even though the badges link elsewhere.
Email providers
The contact link opens email; the sender's provider and the recipient mail system process the message.

What the code fixes, and what it does not

The visitor identifier cookie is configured for ten years. The Google redirect cookie lasts one hour, and the dismissed-prompt preference lasts 24 hours. The application database stores user, Google profile, favorite and tool-submission records without a fixed deletion period in the current repository.

File-based application logs are configured, but no log rotation or retention period is specified here. Email retention depends on the mail systems involved. Third-party analytics, advertising, CDN, badge and destination providers apply their own retention rules.

Security has practical limits

OSINT Tools relies on application, database, hosting and third-party service controls to deliver the site. No web transmission, database or external provider can be represented as completely secure. Avoid sending information that is not necessary for the feature or enquiry you are using.

Controls available to visitors

  • Browse without connecting a Google account.
  • Remove individual favorites through the favorites interface.
  • Delete or block site cookies in your browser; this can break continuity for saved favorites, unbound submissions and sign-in.
  • Use the logout action to clear the visitor identifier cookie from that browser. Logging out does not itself delete existing database records.
  • Review or revoke OSINT Tools access from your Google account controls.
  • Use browser privacy controls for analytics, advertising and third-party assets.

Questions about a site user record or privacy request can be sent to the contact address below. Include enough information to identify the relevant record, but do not send a password or authentication code.

A general research directory, not a children's service

The site is not designed specifically for children and does not ask visitors to provide an age. If a parent or guardian believes a child has provided personal information through Google sign-in or email, they can contact the site with the relevant details.

Policy revisions

This page may be revised when site features, providers or data flows change. The date at the top records the latest published revision. Earlier wording should not be relied on to describe a newer version of the application.

Privacy questions

Send questions about this policy or a site user record to the address below. For directory content corrections, the contact guide provides a more specific report format.

Privacy contact [email protected]